6 ms·
I didn't go to MIT, so I may just be talking out my ass here, but here goes. While I think this is a good step in the right direction, there is no technologica
by jdechko 13y ago
I didn't go to MIT, so I may just be talking out my ass here, but here goes.
While I think this is a good step in the right direction, there is no technological solution for the real problem:
AVERAGE USERS ARE IDIOTS
They use dictionary passwords. They write them down on post-it notes. They re-use passwords.
Try as we may to enlighten people. They are still stuck in their ways. The only thing we can really attempt to do is force people to add complexity (#1).
Security is only as strong as its weakest link. I'm glad that companies take my security seriously, and I hope this idea catches on to strengthen that security. But it's only a small step overall.
- bluedino 13y agoThis doesn't try to solve any of those problems - it's basically a honeypot system to detect when a password file has been leaked and logins are being extracted (and used) from it.
- khafra 13y agoIt certainly helps when we use password-based key derivation functions instead of cryptographic hashes in our applications. The difference between md5 and bcrypt with a high work factor is like the difference between Pa$$word01 and t8LIO.>5row8VEgf
- jfb 13y agoUsers aren't idiots. They're trying to get shit done, and these stupid and arbitrary rules about passwords are hindering their ability. They're stuck in their ways because holding the computer's hand is a waste of time. Forcing them to add complexity has already failed, because fundamentally it's not a humane solution to the problem.
- vec 13y agoThis times a lot. I'm far from a naive user, but I recycle a handful of easily memorable passwords for most of the services I subscribe to. And I'm willing to bet that most of you do too. Security is a tradeoff, and we tend to forget that complex, unique passwords have a very real cost. They drastically increase the risk that I will lock myself out of some service, and dramatically increase the workload of authorizing myself when I do want to use it. With a few obvious exceptions, this tradeoff is a huge net loss for the average user. In other words, the risk of some stranger wanting to post as me in HN is acceptably small. The cost of having to install KeePassX, then download my passwords file from Dropbox then decrypt and copy/paste, then make sure the paste register is clear, then securely delete my passwords file every time I borrow a friend's computer is prohibitively high.
- marshray 13y agoJust write your passwords down in a safe place.
- evolve2k 13y agoReal question: assuming you live alone is 'next to your computer' eg in your own home considered a safe place? What's the risk of a physical robber stealing bits of paper next to your computer desk then hacking your accounts?
- scott_karana 13y agoThe risk, I suspect, is considerably LOWER than having a password guessed by a brute-forcing script on the Internet. Thievery isn't typically a frequently recurring operation, and when it occurs, the user is apt to notice.
- eli 13y agoWell, consider that if an attacker has physical access to your computer there's a pretty good chance you are screwed even if your password isn't written on a sticky note under the keyboard.
- jfb 13y agoAnd you're much more likely to be aware of the intrusion.
- marshray 13y agoThe category of attackers who are willing and able to commit a (possibly violent) physical crime to obtain one or more of my login passwords is much smaller than those who will successfully exploit weak and re-used passwords over the internet.
- dredmorbius 13y ago"A safe place" really depends on your threat model. If you live in a place where home entries by persons with an interest in your online accounts is common, then no, your home would not be a safe place. This could include: living under an oppressive nondemocratic regime, living in a democratic regime with broad search and investigation rules, living with your snooping parents, having an ex with (authorized or otherwise) access to your home, roommates, roommates friends, being a highly social person hosting parties and not being able to secure your computer area. Among others. A friend tells doing consulting work with a national diplomatic corps in a foreign country, using his personal Linux laptop, had the device scanned on his exiting the country by a known, trusted, and competent security expert. Several surveillance mechanisms were detected. The offices of faculty and staff at major universities associated with that foreign country are also subject to surveillance software, according to the same source. Those offices and the buildings they are in, as well as the associated computer networks, are generally readily accessible. Computers are complex enough, even for sophisticated users, to be difficult to secure completely. An advantage of physical, nondigital records of passwords is that they provide a much smaller attack surface. Computers (especially always-on systems) can be attacked from anywhere on the Internet (at least in theory). A slip of paper concealed in some out-of-the-way place in your home is much less likely to be found, though unless it's encrypted, it's much more likely to be useful if found.
- jnazario 13y agoForcing them to add complexity has already failed there is nothing extra the user has to do, which is explicitly stated in the paper.
- jfb 13y agoSorry, infelicitous language on my part. Read that as: Forcing the users to add complexity ... I think the honeyword concept is very clever. The idea that the same broken security paradigm ONLY THIS TIME EMBIGGENED will work, where its been doing nothing but failing until now, seems like magical thinking.
- lobotryas 13y agoIt's a delicate balance between accessibility (to your site and product) and good security practices (forced periodic password resets, force the use of special characters in passwords, etc). The approach I like best so far is screening for the 1,000 or so most common passwords during account registration. Lists of these passwords are available from the Twitter Most Common Password list[0] or other leaks. If the user picks a password form this list then I politely ask them to pick another password. Optional: Suggest passwords to users! Write a simple generator that mixes two inoffensive dictionary words, a few numbers and a symbol into a string that should be fairly easy to memorize (ex: 9Nitrogenchair$) to make the password-picking job easier for them. [0] - http://elementdesignllc.com/2009/12/twitters-most-common-passwords/ http://elementdesignllc.com/2009/12/twitters-most-common-pas...
- dllthomas 13y ago> AVERAGE USERS ARE IDIOTS Please. Technical users are often idiots as well.
- marshray 13y agoI know I am.
- gijjk 13y agoa post-it note is nearly impossible to hack -- only a high-value unsecured physical space can compromise a post-it note. Sniffing a password over the Internet/LAN is far easier.
- dredmorbius 13y agoThere's forcing users to add complexity. And there's recognizing that a known password, or knowable password, is a poor password. There are existing lists of millions of known passwords recovered from various hack attacks and break-ins. Weakness follows a Poisson distribution, with the weakest 10, 50, 100, 500, 1000, ... etc, catching progressively more user accounts. Instituting systems to check against know passwords, or even subsets of the list, when generating an account, on login, or even with regular attempts against known accounts to reject poor passwords, force password changes, or identify poorly-secured accounts is within the realm of technical feasibility. It's functionality which should (in the "would be a good thing to", not "it does" sense) exist in common development toolkits. Better would be obsoleting password-based authentication in favor of key-based challenge-response, but support of this within browsers (yay! centralized implementation point), apps (oh crap....), and other tools (more oh crap) is still years off (despite being called for for years). There's still the matter of master security over a device or authentication system, but we can get away from the present problem of users sharing weak passwords across large numbers of sites.